Data Processing Agreement
Last updated: 28 July 2026
When you use SeatPlanning to collect and manage guest information for your events, you act as the data controller and SeatPlanning acts as your data processor under Art. 28 GDPR.
This page sets out the terms on which we process guest personal data on your behalf. By using guest-facing features (such as RSVP collection) you agree to this Data Processing Agreement. For a countersigned copy, contact contact@seatplanning.com.
1. Roles
You (the account holder / event organizer) are the controller of the guest data you collect. SeatPlanning is the processor and processes that data only on your documented instructions, which are given through your use of the service.
2. Subject matter and duration
We process guest data for the purpose of providing the seating-chart and RSVP service, for as long as you maintain the related chart/account. Data is deleted when you delete the chart or your account, including the delivery history for messages sent to your guests. The one exception is our suppression list of addresses that bounced or complained, which we keep so that those people are not emailed again.
3. Nature and purpose of processing
Collecting RSVPs, organizing seating, sending event-related emails on your behalf, and generating exports and entry tickets.
4. Categories of data subjects and data
Data subjects are your event guests. Data may include names, email addresses, phone numbers, seating and attendance records, and any RSVP fields you configure—which can include dietary, allergy or accessibility information that constitutes special-category data under Art. 9 GDPR.
You decide which fields to collect and you are responsible for having a lawful basis for them, including the explicit consent that Art. 9(2)(a) GDPR requires for health-related answers. We provide these fields as free text and do not classify or separately protect their content.
5. Our obligations
- Process guest data only on your instructions
- Ensure persons authorized to process data are bound by confidentiality
- Implement appropriate technical and organizational security measures
- Assist you with data-subject requests and security/breach obligations
- Notify you without undue delay after becoming aware of a personal data breach affecting your guest data
- Make available the information needed to demonstrate compliance with Art. 28 GDPR
- Delete or return guest data on termination, subject to legal retention
6. Sub-processors
You authorize us to engage the sub-processors listed in our Privacy Policy. They are bound by equivalent data-protection obligations. We will inform you of intended changes and give you the opportunity to object.
7. International transfers
Where sub-processors process data outside the EEA, transfers are protected by appropriate safeguards under Chapter V GDPR, being the EU Standard Contractual Clauses and, where applicable, certification under the EU-U.S. Data Privacy Framework. Our Privacy Policy lists which providers are concerned.
8. Your responsibilities
You are responsible for informing your guests how their data is used, for having a lawful basis to collect it, and for deciding who receives a public chart or invite link. Publishing a chart or sharing an invite link makes guest names, RSVP status and seat visible to anyone holding that link.
9. Contact
For DPA requests or a signed copy, contact contact@seatplanning.com.